Asymmetric multi-core AMP time-sharing cycle working method
By adopting the time-sharing cycle working method in asymmetric multi-core AMP mode, ensuring that the processor cores work in sequence and update the health flags in real time, the problem of uncertainty in the sequence of behavior of the processor core is solved, and the system is determinability and usability are improved.
Patent Information
- Application Number
- CN202111539445.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-15
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-12-15
AI Technical Summary
In asymmetric multi-core AMP mode, the uncertainty of the sequence of functional behavior between processor cores causes the system to suffer safety and reliability in areas where order is strictly required (such as spacecraft control).
The asymmetric multi-core AMP time-sharing cycle working method is adopted. By setting the processor cores to be awakened in sequence and execute their respective programs, the general counter is used to generate the working time window and handover time window of each core, and the core health flag is initialized and updated in real time, ensuring that only one core is in the working state within each time window, the other cores are suspended, and the dog feeding program is completed by the current core.
The orderly working of the processor core is realized, the overhead of resource conflicts is reduced, and the system is improved. Even if there are multiple core failures, as long as one core is normal, the system can still maintain normal working state.
Smart Images

Figure CN114237954B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the technical field of embedded multi-core computer systems, in particular to an asymmetric multi-core AMP time-sharing cycle working method. Background Art
[0002] Multi-core processors generally operate in Symmetry MultiProcessing (SMP) mode or AMP mode. In SMP mode, all processor cores in the processor are managed uniformly by one operating system or one application, and have a unified memory space. In AMP mode, each processor core in the processor has its own independent memory space, and each runs an operating system or application independently, with only a small amount of information exchange between processor cores. In AMP mode, the operating systems or applications running on each processor core may be the same or different, that is, the functional behaviors of each core may be the same or different. The present invention only relates to AMP mode.
[0003] When a multi-core processor is started, one core is usually responsible for performing system initialization work. This core is called the master core, and the other cores are called slave cores. After the master core completes the initialization work, it is responsible for external data communication and wakes up other slave cores according to task requirements. The slave cores independently perform their respective functions according to pre-set program settings. Since multiple processor cores share the system bus, memory, I / O interface and other resources inside the processor, in order to avoid conflicts caused by multiple processor cores reading and writing shared resources at the same time, resulting in data errors or abnormal operations, it is necessary to synchronize the access to multi-core shared resources, such as locking, so that only one processor core can obtain and control shared resources at the same time, and the other cores wait for the release of shared resources.
[0004] However, the process of processor cores obtaining resources through locking has certain uncertainty, that is, the order of processor cores that grab locks is affected by various factors such as different startup timing, different running times of different core functions, external interrupts, etc., which has certain randomness. This makes the order of each processor core in performing its functional behavior also have certain randomness. In fields that have strict order requirements for the functional behavior of each core, or fields that have strong requirements for the determinism of the order of functional behavior, such as spacecraft control, the uncertainty of the order of processor behavior will have an adverse impact on the security and reliability of the system.
[0005] The processor architecture usually contains a hardware component counter of the watchdog, which is set to a certain value and then decrements to zero. It is the responsibility of the software to frequently set the count to its original value to ensure that the count never reaches zero. If it does reach zero, it is assumed that the software has failed in some way and the CPU has been reset. When the main core has a program runaway or a functional interrupt failure due to the influence of a harsh environment, regardless of whether the other slave cores are normal, the entire processor will cause the system to reset due to failure to feed the dog in time. Summary of the invention
[0006] The purpose of the present invention is to provide an asymmetric multi-core AMP time-sharing cycle working method to solve the problems raised in the above background technology.
[0007] The asymmetric multi-core AMP time-sharing cycle working method comprises:
[0008] Step 1: The step 1 includes setting the process of waking up each core of the processor in sequence and executing their respective programs;
[0009] Step 2: The step 2 includes using a universal counter of a multi-core processor to generate a working time window for each processor core and a handover time window between different processor cores, and setting a maximum running time for each working time window and handover time window;
[0010] Step 3: Step 3 includes the process of initializing and updating the health flag of the processor core in real time;
[0011] Step 4: The step 4 includes setting, in each working time window, only one core of the processor is in working state, and the other cores are in suspended state, and setting a watchdog program, and the processor core currently in working state completes the watchdog feeding program; and:
[0012] When the working time of the processor core in the window reaches the maximum working time window, the current processor core automatically enters the suspended state and wakes up the next processor core in the specified order;
[0013] If the next core is not awakened within the preset handover time window, the next core is judged to be faulty, and the current processor core wakes up another processor core in sequence until the awakening of the other processor core is completed within the preset handover time window;
[0014] The awakened processor core takes over the system and executes its program.
[0015] Furthermore, the specific steps of step 2 include:
[0016] Set the processor core number 0,1,2,...,n, where n is the maximum number of cores in the processor, and the processor core numbered i is called core i;
[0017] The working time window of core i is called working window i, and the time width of working window i is set;
[0018] The handover time window of core i is called handover window i, and the time width of handover window i is set.
[0019] In step 4, the execution process of core i is as follows:
[0020] S12. Core i is awakened, and core i first initializes the general counter of the processor, and then starts the counter to start counting;
[0021] S13. Core i runs its own functional program;
[0022] S14. When the count value of the general counter meets the set value of window i, interrupt A is triggered;
[0023] S15. Core i responds to interrupt A and enters the service routine of interrupt A;
[0024] S16. Determine whether there are any available cores. If there are, let (i+1) be the number of the next available core. If i is the maximum number of available cores, let (i+1) be the minimum number of available cores, and jump to step S6. If there are no available cores, let (i+1) be the current core itself, and jump to step S1.
[0025] S17. Core i wakes up core (i+1);
[0026] S18. Core i generates interrupt B and transmits it to core (i+1) through the inter-core interrupt mechanism;
[0027] S19. Query flag, if:
[0028] S8.1 The flag is modified within the handover window, and the core (i+1) is considered healthy, and the process jumps to step S9;
[0029] S8.2 If the flag is not modified within the handover window, it is determined that core (i+1) is faulty, the health record table of the processor core is modified, and the process goes to step S5;
[0030] S20. Core i initializes and starts the counter;
[0031] S21. Core i wakes up core (i+1) again, and core (i+1) controls the system;
[0032] S22. Core i enters the suspended state by itself and waits to be woken up again.
[0033] Furthermore, the execution process of core i+1 is as follows:
[0034] P5. Corresponding to S6, core i wakes up core (i+1), and core (i+1) is awakened; if it is not the first time to be awakened, core (i+1) automatically exits the previous interrupt A service program after being awakened from suspension; if core (i+1) is not awakened due to various reasons, core (i+1) cannot complete the modification of the flag in S3, and the situation is handled according to S8;
[0035] P6. Corresponding to S7, core (i+1) responds to interrupt B transmitted by core i and enters the service routine of interrupt B;
[0036] P7. Corresponding to S8, modify the flag in the service program of interrupt B;
[0037] P8. Core (i+1) enters the suspended state by itself, waiting to be awakened again.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] First, the present invention sets only one processor core to work in the same time period, which can reduce the overhead caused by conflicts caused by simultaneous access to resources;
[0040] Second, the processor's multiple cores work one by one in a preset order, which can ensure the execution order of multi-core functions and make the multi-core processor behavior show good determinism;
[0041] Third, the dog feeding is completed by the current processor core. Even if n-1 cores fail, as long as the current processor core can work normally, the system can maintain a normal working state, thereby improving system availability. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 This is a schematic diagram of the structure of a quad-core processor in AMP mode;
[0043] Figure 2 It is a time-sharing cycle workflow diagram;
[0044] Figure 3 This is a schematic diagram of time-sharing cycle operation under normal conditions;
[0045] Figure 4 for Figure 1 A schematic diagram of the time-sharing cycle operation after a nuclear failure occurs;
[0046] Figure 5 for Figure 1 The following is a schematic diagram of the time-sharing cycle operation when two cores fail;
[0047] Figure 6 for Figure 1 Schematic diagram of the time-sharing cycle operation that occurs when three cores fail. DETAILED DESCRIPTION
[0048] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0049] See also Figure 1-6 ,Asymmetric multi-core AMP time-sharing cycle working method,Step 1: Set each core of the processor to execute its own program in sequence;
[0050] Step 2: Use the universal counter of the multi-core processor to generate the working time window of each processor core and the handover time window between different processor cores, and set the maximum running time of each working time window and handover time window;
[0051] Step 3: Initialize and update the health flag of the processor core in real time;
[0052] Step 4: In each working time window, set the process that only one core of the processor is in working state and the other cores are in suspended state, and set the watchdog program, and the processor core currently in working state completes the watchdog feeding program; and:
[0053] When the working time of the processor core in the window reaches the maximum working time window, the current processor core automatically enters the suspended state and wakes up the next processor core in the specified order;
[0054] If the next core is not awakened within the preset handover time window, the next core is judged to be faulty, and the current processor core wakes up another processor core in sequence until the awakening of the other processor core is completed within the preset handover time window;
[0055] The awakened processor core takes over the system and executes its program.
[0056] The specific steps of step 2 include:
[0057] Set the processor core number 0,1,2,...,n, where n is the maximum number of cores in the processor, and the processor core numbered i is called core i;
[0058] The working time window of core i is called working window i, and the time width of working window i is set;
[0059] The handover time window of core i is called handover window i, and the time width of handover window i is set.
[0060] In step 4, the execution process of core i is as follows:
[0061] S23. Core i is awakened, and core i first initializes the general counter of the processor, and then starts the counter to start counting;
[0062] S24. Core i runs its own functional program;
[0063] S25. When the count value of the general counter meets the set value of window i, interrupt A is triggered;
[0064] S26. Core i responds to interrupt A and enters the service routine of interrupt A;
[0065] S27. Determine whether there are any available cores. If there are, let (i+1) be the number of the next available core. If i is the maximum number of available cores, let (i+1) be the minimum number of available cores, and jump to step S6. If there are no available cores, let (i+1) be the current core itself, and jump to step S1.
[0066] S28. Core i wakes up core (i+1);
[0067] S29. Core i generates interrupt B and transmits it to core (i+1) through the inter-core interrupt mechanism;
[0068] S30. Query flag, if:
[0069] S8.1 The flag is modified within the handover window, and the core (i+1) is considered healthy, and the process jumps to step S9;
[0070] S8.2 If the flag is not modified within the handover window, it is determined that core (i+1) is faulty, the health record table of the processor core is modified, and the process goes to step S5;
[0071] S31. Core i initializes and starts the counter;
[0072] S32. Core i wakes up core (i+1) again, and core (i+1) controls the system;
[0073] S33. Core i enters the suspended state by itself and waits to be awakened again.
[0074] The execution process of core i+1 is as follows:
[0075] P9. Corresponding to S6, core i wakes up core (i+1), and core (i+1) is awakened; if it is not the first time to be awakened, core (i+1) automatically exits the previous interrupt A service program after being awakened from suspension; if core (i+1) is not awakened due to various reasons, core (i+1) cannot complete the modification of the flag in S3, and handles this situation according to S8;
[0076] P10. Corresponding to S7, core (i+1) responds to interrupt B transmitted by core i and enters the service routine of interrupt B;
[0077] P11. Corresponding to S8, modify the flag in the service program of interrupt B;
[0078] Core (i+1) enters the suspended state by itself, waiting to be woken up again.
[0079] Embodiment 1:
[0080] Taking the Leon3 / 4 processor as an example, the specific implementation of the time-sharing loop workflow is explained. The processor is set to 4 cores; the general counter uses interrupt 9; and the inter-core interrupt uses interrupt 8.
[0081] Specific implementation process of Core 0:
[0082] After the processor is started, only core 0 is in working state, and other cores are automatically in suspended (power-down) state.
[0083] (1) Enter core 0, complete the mounting of interrupts 8 and 9, and clear the interrupt mask. Core 0 initializes the general counter of the processor. First, set the counter control register to all 0s, then set the counter load ratio register to all 0s, set the working time length in the counter load value register, such as 0x00F00000, and finally write 0x0000000F in the counter control register to start the counter counting. The counter will start to decrement from 0x00F00000 and generate an interrupt when it reaches 0x0.
[0084] (2) Core 0 runs its own functional program, such as performing matrix multiplication with a dimension of 32*32.
[0085] (3) When the count value of the general counter decreases from 0x00F00000 to 0x0 and meets the set length value of the working time window, interrupt 9 is triggered.
[0086] (4) Core 0 responds to interrupt 9 and enters the service routine of interrupt 9.
[0087] (5) In the interrupt service program, determine whether there are any available cores. If there are, let (i+1) be the number of the next available core, such as core 1, and jump to step (6); if there are no other available cores except the current core, the next available core is the current core itself, that is, core 0, and jump to step (1).
[0088] (6) Core 0 uses an assembly statement to write 1 to the second bit of the Status field of the multi-core status register MSR corresponding to core 1 to wake up core 1.
[0089] (7) Subsequently, core 0 forces interrupt 8 to be generated in core 1 by setting the corresponding position of the interrupt force register corresponding to the next available core, such as core 1, to 1.
[0090] (8) Core 0 query flag, there are two cases:
[0091] (8.1) Within the handover window, the flag is modified, and core 1 is considered healthy, so jump to step (9).
[0092] (8.2) If flag is not modified within the handover window, it is determined that core 1 has failed, the health record table of the processor core is modified, and the process goes to step (5).
[0093] (9) Core 0 initializes again and starts the counter.
[0094] (10) Core 0 wakes up core 1 again, and the operation is the same as step (6).
[0095] (11) Core 0 writes all 0s to register %asr19 through the assembly statement wrasr, causing core 0 to enter the suspended (power-down) state by itself.
[0096] Specific implementation process of Core 1:
[0097] (1) Core 1 is awakened (corresponding to step (6) of core 0). If this is not the first time that core 1 is awakened, core 1 awakened from the suspended state will automatically exit the service routine of the previous interrupt 9.
[0098] (2) Core 1 responds to interrupt 8 transmitted from core 0 and enters the service routine of local interrupt 8 (corresponding to step (7) of core 0).
[0099] (3) Modify the flag in the service routine of interrupt 8 (corresponding to step (8) of core 0).
[0100] (4) Core 1 writes all 0s to register %asr19 through the assembly statement wrasr, causing core 1 to enter the suspended (power-down) state by itself.
[0101] (5) Core 1 is awakened again by core 0 (corresponding to step (10) of core 0).
[0102] (6) This step is the same as step (1) of the original core 0. At this point, core 0 and core 1 have completed the handover, and core 1 has transformed into the role of the original core 0 and controls the computer system.
[0103] (7) The subsequent steps of core 1 are the same as step (2) and its subsequent steps of the original core 0.
[0104] The current processor core is triggered to execute the dog feeding program in interrupt mode. The interrupt priority is higher than other interrupts, ensuring that as long as one core is normal, the system can continue to feed the dog and maintain work.
[0105] For core 1, if it is not awakened due to various reasons, core 1 cannot complete the modification of the flag in step (3). Correspondingly, core 0 has different branches in step (8) to handle this situation.
[0106] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. Asymmetric multi-core AMP time-sharing cycle working method, characterized in that: It includes: Step 1: The step 1 includes setting the process of waking up each core of the processor in sequence and executing their respective programs; Step 2: The step 2 includes using a universal counter of a multi-core processor to generate a working time window for each processor core and a handover time window between different processor cores, and setting a maximum running time for each working time window and handover time window; Step 3: Step 3 includes the process of initializing and updating the health flag of the processor core in real time; Step 4: The step 4 includes setting, in each working time window, only one core of the processor is in working state, and the other cores are in suspended state; and setting a watchdog program, and the processor core currently in working state completes the watchdog feeding program; and: When the working time of the processor core in the window reaches the maximum working time window, the current processor core automatically enters the suspended state and wakes up the next processor core in the specified order; If the next core is not awakened within the preset handover time window, the next core is judged to be faulty, and the current processor core wakes up another processor core in sequence until the awakening of the other processor core is completed within the preset handover time window; The awakened processor core takes over the system and executes its program.
2. The asymmetric multi-core AMP time-sharing cycle working method according to claim 1, characterized in that: The specific steps of step 2 include: Set the processor core number 0,1,2,...,n, where n is the maximum number of cores in the processor, and the processor core numbered i is called core i; The working time window of core i is called working window i, and the time width of working window i is set; The handover time window of core i is called handover window i, and the time width of handover window i is set.
3. The asymmetric multi-core AMP time-sharing cycle working method according to claim 2 is characterized in that: In step 4, the execution process of core i is as follows: S1. Core i is awakened. Core i first initializes the general counter of the processor and then starts counting. S2. Core i runs its own functional program; S3. When the count value of the general counter meets the set value of window i, interrupt A is triggered; S4. Core i responds to interrupt A and enters the service routine of interrupt A; S5. Determine whether there are any available cores. If there are, let (i+1) be the number of the next available core. If i is the maximum number of available cores, let (i+1) be the minimum number of available cores, and jump to step S6. If there are no available cores, let (i+1) be the current core itself, and jump to step S1. S6. Core i wakes up core (i+1); S7. Core i generates interrupt B and transmits it to core (i+1) through the inter-core interrupt mechanism; S8. Query flag, if: S8.1 The flag is modified within the handover window, and the core (i+1) is considered healthy, and the process jumps to step S9; S8.2 If the flag is not modified within the handover window, it is determined that core (i+1) is faulty, the health record table of the processor core is modified, and the process goes to step S5; S9. Core i initializes and starts the counter; S10. Core i wakes up core (i+1) again, and core (i+1) controls the system; S11. Core i enters the suspended state by itself and waits to be woken up again.
4. The asymmetric multi-core AMP time-sharing cycle working method according to claim 3 is characterized in that: The execution process of core i+1 is as follows: P1. Corresponding to S6, core i wakes up core (i+1), and core (i+1) is awakened; if it is not the first time to be awakened, core (i+1) automatically exits the previous interrupt A service program after being awakened from suspension; if core (i+1) is not awakened due to various reasons, core (i+1) cannot complete the modification of the flag in S3, and the situation is handled according to S8; P2. Corresponding to S7, core (i+1) responds to interrupt B transmitted by core i and enters the service routine of interrupt B; P3. Corresponding to S8, modify the flag in the service program of interrupt B; P4. Core (i+1) enters the suspended state by itself, waiting to be awakened again.
Citation Information
Patent Citations
Asymmetric multi-core system and realization method thereof
CN102662740A
Transient fault restoration system and transient fault restoration method of separated log based multi-core processor
CN104657239A